import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages a CloudWatch Observability Admin S3 Table Integration. This integration enables CloudWatch to duplicate telemetry data to Amazon S3 Tables, making it available for analysis by tools such as Amazon Athena and Amazon Redshift. * * For more information, see the [CloudWatch Logs S3 Tables integration documentation](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/s3-tables-integration.html). * * ## Example Usage * * ### Basic Integration with AES256 Encryption * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.iam.Role("example", { * name: "example-s3-table-integration", * assumeRolePolicy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Action: "sts:AssumeRole", * Effect: "Allow", * Principal: { * Service: "logs.amazonaws.com", * }, * }], * }), * }); * const exampleRolePolicy = new aws.iam.RolePolicy("example", { * role: example.name, * policy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Effect: "Allow", * Action: [ * "s3tables:CreateTableBucket", * "s3tables:ListTableBuckets", * "s3tables:GetTableBucket", * "s3tables:CreateNamespace", * "s3tables:GetNamespace", * "s3tables:ListNamespaces", * "s3tables:CreateTable", * "s3tables:GetTable", * "s3tables:ListTables", * "s3tables:PutTableData", * "s3tables:GetTableData", * ], * Resource: "*", * }], * }), * }); * const exampleS3TableIntegration = new aws.observabilityadmin.S3TableIntegration("example", { * encryption: { * sseAlgorithm: "AES256", * }, * roleArn: example.arn, * }); * ``` * * ### Integration with KMS Encryption * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.iam.Role("example", { * name: "example-s3-table-integration", * assumeRolePolicy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Action: "sts:AssumeRole", * Effect: "Allow", * Principal: { * Service: "logs.amazonaws.com", * }, * }], * }), * }); * const exampleKey = new aws.kms.Key("example", { * description: "S3 Table Integration KMS key", * deletionWindowInDays: 7, * }); * const exampleS3TableIntegration = new aws.observabilityadmin.S3TableIntegration("example", { * encryption: { * sseAlgorithm: "aws:kms", * kmsKeyArn: exampleKey.arn, * }, * roleArn: example.arn, * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `arn` (String) ARN of the S3 Table integration. * * Using `pulumi import`, import CloudWatch Observability Admin S3 Table Integrations using the `arn`. For example: * * ```sh * $ pulumi import aws:observabilityadmin/s3TableIntegration:S3TableIntegration example arn:aws:observabilityadmin:us-east-1:123456789012:s3-table-integration/example-id * ``` */ export declare class S3TableIntegration extends pulumi.CustomResource { /** * Get an existing S3TableIntegration resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: S3TableIntegrationState, opts?: pulumi.CustomResourceOptions): S3TableIntegration; /** * Returns true if the given object is an instance of S3TableIntegration. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is S3TableIntegration; /** * ARN of the S3 Table integration. */ readonly arn: pulumi.Output; /** * ARN of the S3 Table bucket where CloudWatch data is stored. AWS automatically creates a bucket named `_aws-cloudwatch_` if one does not already exist. */ readonly destinationTableBucketArn: pulumi.Output; /** * Encryption configuration block. Documented below. */ readonly encryption: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ARN of the IAM role that grants the S3 Table integration permissions to access necessary resources. */ readonly roleArn: pulumi.Output; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Create a S3TableIntegration resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: S3TableIntegrationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering S3TableIntegration resources. */ export interface S3TableIntegrationState { /** * ARN of the S3 Table integration. */ arn?: pulumi.Input; /** * ARN of the S3 Table bucket where CloudWatch data is stored. AWS automatically creates a bucket named `_aws-cloudwatch_` if one does not already exist. */ destinationTableBucketArn?: pulumi.Input; /** * Encryption configuration block. Documented below. */ encryption?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of the IAM role that grants the S3 Table integration permissions to access necessary resources. */ roleArn?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a S3TableIntegration resource. */ export interface S3TableIntegrationArgs { /** * Encryption configuration block. Documented below. */ encryption: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of the IAM role that grants the S3 Table integration permissions to access necessary resources. */ roleArn: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=s3tableIntegration.d.ts.map